Securing the email account that runs your business

Securing the email account that runs your business

Membergate Support -

Think about what happens when you click “Forgot password” on almost any service. A reset link arrives in your email. That means whoever controls your business inbox can, within minutes, get into your membership platform, payment processor, domain registrar, email marketing service and social accounts. Your inbox is not one account among many. It is the master key to nearly all of them.

It is also a treasure chest. Years of member conversations, invoices, contracts, exported spreadsheets and passwords someone sent you “just this once” sit in its folders. The email account that runs your business deserves more protection than any other single account you have.

Use a business address you control

Many membership businesses start on a free personal email address and never move. That creates two problems. The account belongs to you personally rather than the business, so if you lose it, recovery depends on a consumer support process. And every service you have ever signed up for is tied to it.

An address on your own domain, run through a business email service, gives you more control: you can add team mailboxes, manage recovery and keep addresses when people come and go. It also makes securing your domain name and DNS even more important, because your email now depends on your domain.

Lock the front door

  • A long, unique password used nowhere else and stored in a password manager.
  • Two-factor authentication, preferably with a security key or authenticator app rather than text messages. This one step does more than anything else in this article.
  • Recovery codes saved somewhere that does not depend on the inbox itself, such as a printed copy kept somewhere secure.

Check the back doors

Attackers who get into an inbox often leave quiet ways to keep watching it, even after you change the password. Legitimate settings you added years ago can do the same job for them. Look at each of these:

  1. Recovery email and phone number. Are they current, and are they yours? An old recovery address at a former job, or a phone number you gave up, can be used to take over the account.
  2. Forwarding and filter rules. A rule that forwards copies of messages to an outside address, or quietly moves emails containing words like “password” or “invoice” into a folder you never open, is a classic sign of compromise.
  3. Delegates and shared access. Anyone given permission to read or send as you, such as a former assistant.
  4. Connected apps. Services you allowed to read your mail or calendar, such as a scheduling tool or an email add-on you tried once. Each can read your messages for as long as the approval stands.
  5. App passwords. Older email programs sometimes use special passwords that bypass two-factor authentication. Remove any you do not recognize or no longer need.
  6. Active sessions and devices. Sign out anything you do not recognize, along with old devices you no longer use.

Separate your most critical accounts

Your public business address appears on your website, emails and receipts, so it is the one scammers target. For the few accounts that could do the most damage, consider a separate, private address that is never published: your domain registrar, payment processor, bank and the owner account on your membership platform. Protect it just as strongly. An attacker who phishes your public address then does not automatically reach the accounts that control your money and your domain.

For team work, use shared role mailboxes such as a support address, with each person signing in with their own credentials rather than sharing one password. Then you can remove one person without changing everything, as part of offboarding staff and contractors securely.

Clean out what you do not need to keep

An inbox that holds everything forever is a bigger prize. Search for and delete:

  • Member exports and spreadsheets sent as attachments.
  • Passwords, access keys and recovery codes sent by email.
  • Card numbers or identity documents members sent to support.
  • Old conversations containing sensitive personal details you no longer need.

Empty the trash afterward, since deleted items often sit there for weeks.

A worked example: a thirty-minute inbox audit

Ines runs a hypothetical pottery membership from a free email address she set up long ago. She sets aside thirty minutes and works through this sequence:

  1. She changes her password to a long generated one and turns on two-factor authentication with an authenticator app, writing the recovery codes on paper.
  2. She finds her recovery phone number is one she gave up years ago, and updates it.
  3. In the settings she finds a rule forwarding copies of all mail to an address she does not recognize and never created. She deletes it, signs out every session and checks the activity logs in her payment processor and membership platform for anything that changed.
  4. She removes four connected apps she no longer uses.
  5. She searches for “password” and “export” and deletes a dozen messages she should never have kept.

The forwarding rule turned a routine audit into a small incident, but she caught it. Her next project is moving the business onto an address on her own domain, with a separate private address for her payment and registrar accounts.

Your next steps

  1. Turn on two-factor authentication for your business email today and save the recovery codes.
  2. Check recovery details, forwarding rules, delegates, connected apps, app passwords and sessions.
  3. Delete sensitive attachments and passwords from old mail, then empty the trash.
  4. Plan a move to an address on your own domain if you are still using a personal account.
  5. Set up a private address for your most critical accounts.
  6. Repeat the audit every few months.

0 Comments

Comments are reviewed before they appear.